Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
“Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis, Chief Information Security Officer (CISO) at Kiteworks.
“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities.”
The company said it has not found any evidence that its customers’ systems have been compromised, emphasizing the advisory is preventative rather than a response to a confirmed hack. The development was first reported by German news publication Heise.
Kiteworks did not disclose which law enforcement agency alerted the company, or who may be behind it. The American software firm said all known vulnerabilities have been addressed in its latest software release, 9.5.1, recommending that customers apply the patches for optimal protection.
Other subsidiaries of Kiteworks, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, are not affected.
Kiteworks also revealed that it has sent an email to all customers detailing the specific hours as well as the recommended nine-hour timeframe.
In late 2020-early 2021, the Clop threat actor (aka UNC2546) was found exploiting multiple zero-day vulnerabilities in its file transfer program to conduct a data theft and extortion campaign targeting high-profile entities.





